Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-75007

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Aug 17, 2026
Vendor unknown

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

References